
Proof-of-concept exploit for FreePBX Endpoint module CVE-2025-5781: chains unauthenticated SQL injection with database manipulation and scheduled task execution to achieve remote code execution.
In August 2025, a critical vulnerability was disclosed in the FreePBX Endpoint module. CVE-2025–57819 allows an unauthenticated attacker to exploit SQL injection in the Endpoint module and, through a chain of database manipulation and scheduled task execution, achieve remote code execution.